Cargando…

Zero Trust security : an enterprise guide /

Understand how Zero Trust security can and should integrate into your organization. This book covers the complexity of enterprise environments and provides the realistic guidance and requirements your security team needs to successfully plan and execute a journey to Zero Trust while getting more val...

Descripción completa

Detalles Bibliográficos
Clasificación:Libro Electrónico
Autores principales: Garbis, Jason (Autor), Chapman, Jerry W. (Autor)
Formato: Electrónico eBook
Idioma:Inglés
Publicado: [Berkeley, CA] : Apress, [2021]
Temas:
Acceso en línea:Texto completo (Requiere registro previo con correo institucional)

MARC

LEADER 00000cam a2200000 i 4500
001 OR_on1241447515
003 OCoLC
005 20231017213018.0
006 m o d
007 cr cnu---unuuu
008 210313s2021 cau ob 001 0 eng d
040 |a EBLCP  |b eng  |e rda  |e pn  |c EBLCP  |d YDX  |d GW5XE  |d OCLCO  |d N$T  |d EBLCP  |d OCLCF  |d VT2  |d LIP  |d UKAHL  |d OCLCQ  |d OCLCO  |d COM  |d OCLCQ 
019 |a 1240209711  |a 1253416225 
020 |a 9781484267028  |q (electronic bk.) 
020 |a 1484267028  |q (electronic bk.) 
020 |a 9781484267035  |q (print) 
020 |a 1484267036 
020 |z 148426701X 
020 |z 9781484267011 
024 7 |a 10.1007/978-1-4842-6702-8  |2 doi 
029 1 |a AU@  |b 000068885829 
035 |a (OCoLC)1241447515  |z (OCoLC)1240209711  |z (OCoLC)1253416225 
050 4 |a TK5105.59 
072 7 |a COM014000  |2 bisacsh 
072 7 |a UY  |2 bicssc 
072 7 |a UY  |2 thema 
082 0 4 |a 005.8  |2 23 
049 |a UAMI 
100 1 |a Garbis, Jason,  |e author. 
245 1 0 |a Zero Trust security :  |b an enterprise guide /  |c Jason Garbis, Jerry W. Chapman. 
264 1 |a [Berkeley, CA] :  |b Apress,  |c [2021] 
300 |a 1 online resource (306 pages) 
336 |a text  |b txt  |2 rdacontent 
337 |a computer  |b c  |2 rdamedia 
338 |a online resource  |b cr  |2 rdacarrier 
347 |a text file 
347 |b PDF 
504 |a Includes bibliographical references and index. 
520 |a Understand how Zero Trust security can and should integrate into your organization. This book covers the complexity of enterprise environments and provides the realistic guidance and requirements your security team needs to successfully plan and execute a journey to Zero Trust while getting more value from your existing enterprise security architecture. After reading this book, you will be ready to design a credible and defensible Zero Trust security architecture for your organization and implement a step-wise journey that delivers significantly improved security and streamlined operations. Zero Trust security has become a major industry trend, and yet there still is uncertainty about what it means. Zero Trust is about fundamentally changing the underlying philosophy and approach to enterprise securitymoving from outdated and demonstrably ineffective perimeter-centric approaches to a dynamic, identity-centric, and policy-based approach. Making this type of shift can be challenging. Your organization has already deployed and operationalized enterprise security assets such as Directories, IAM systems, IDS/IPS, and SIEM, and changing things can be difficult. Zero Trust Security uniquely covers the breadth of enterprise security and IT architectures, providing substantive architectural guidance and technical analysis with the goal of accelerating your organizations journey to Zero Trust. You will: Understand Zero Trust security principles and why it is critical to adopt them See the security and operational benefits of Zero Trust Make informed decisions about where, when, and how to apply Zero Trust security architectures Discover how the journey to Zero Trust will impact your enterprise and security architecture Be ready to plan your journey toward Zero Trust, while identifying projects that can deliver immediate security benefits for your organization. 
588 0 |a Print version record. 
505 0 |a Intro -- Table of Contents -- About the Authors -- About the Technical Reviewer -- Acknowledgments -- Foreword -- Part I: Overview -- Chapter 1: Introduction -- Chapter 2: What Is Zero Trust? -- History and Evolution -- Forrester's Zero Trust eXtended (ZTX) Model -- Gartner's Approach to Zero Trust -- Our Perspective on Zero Trust -- Core Principles -- Expanded Principles -- A Working Definition -- Zero Trust Platform Requirements -- Summary -- Chapter 3: Zero Trust Architectures -- A Representative Enterprise Architecture -- Identity and Access Management 
505 8 |a Network Infrastructure (Firewalls, DNS, Load Balancers) -- Jump Boxes -- Privileged Access Management -- Network Access Control -- Intrusion Detection/Intrusion Prevention -- Virtual Private Network -- Next-Generation Firewalls -- Security Information and Event Management -- Web Server and Web Application Firewall -- Infrastructure as a Service -- Software as a Service and Cloud Access Security Brokers -- A Zero Trust Architecture -- The NIST Zero Trust Model -- A Conceptual Zero Trust Architecture -- Policy Components -- Types of Policy Enforcement Points -- What Is a Policy Enforcement Point? 
505 8 |a Zero Trust Deployment Models -- Resource-Based Deployment Model -- Enclave-Based Deployment Model -- Cloud-Routed Deployment Model -- Microsegmentation Deployment Model -- Summary -- Chapter 4: Zero Trust in Practice -- Google's BeyondCorp -- PagerDuty's Zero Trust Network -- The Software-Defined Perimeter and Zero Trust -- Mutual TLS Communications -- Single-Packet Authorization -- SDP Case Study -- Zero Trust and Your Enterprise -- Summary -- Part II: Zero Trust and Enterprise Architecture Components -- Chapter 5: Identity and Access Management -- IAM in Review -- Identity Stores (Directories) 
505 8 |a Databases -- LDAP -- Identity-as-a-Service -- Identity Lifecycle -- Lifecycle Management -- Identity Governance -- Access Management -- Authentication -- LDAP -- RADIUS -- SAML -- OAuth2 -- OpenID Connect (OIDC) -- Certificate-Based Authentication -- FIDO2 -- Mobile and Biometrics -- Authorization -- Zero Trust and IAM -- Authentication, Authorization, and Zero Trust Integration -- Enhancing Legacy System Authentication -- Zero Trust as Catalyst for Improving IAM -- Summary -- Chapter 6: Network Infrastructure -- Network Firewalls -- The Domain Name System -- Public DNS Servers 
505 8 |a Private DNS Servers -- Monitoring DNS for Security -- Wide Area Networks -- Load Balancers, Application Delivery Controllers, and API Gateways -- Web Application Firewalls -- Summary -- Chapter 7: Network Access Control -- Introduction to Network Access Control -- Zero Trust and Network Access Control -- Unmanaged Guest Network Access -- Managed Guest Network Access -- Managed vs. Unmanaged Guest Networks: A Debate -- Employee BYOD -- Device Posture Checks -- Device Discovery and Access Controls -- Summary -- Chapter 8: Intrusion Detection and Prevention Systems -- Types of IDPS 
590 |a O'Reilly  |b O'Reilly Online Learning: Academic/Public Library Edition 
650 0 |a Computer networks  |x Security measures. 
650 6 |a Réseaux d'ordinateurs  |x Sécurité  |x Mesures. 
650 7 |a Computer networks  |x Security measures.  |2 fast  |0 (OCoLC)fst00872341 
700 1 |a Chapman, Jerry W.,  |e author. 
776 0 8 |i Print version:  |a Garbis, Jason.  |t Zero Trust Security : An Enterprise Guide.  |d Berkeley, CA : Apress L.P., ©2021  |z 9781484267011 
856 4 0 |u https://learning.oreilly.com/library/view/~/9781484267028/?ar  |z Texto completo (Requiere registro previo con correo institucional) 
938 |a Askews and Holts Library Services  |b ASKH  |n AH38627740 
938 |a ProQuest Ebook Central  |b EBLB  |n EBL6509882 
938 |a EBSCOhost  |b EBSC  |n 2802247 
938 |a YBP Library Services  |b YANK  |n 17270067 
994 |a 92  |b IZTAP